Trojan

Trojan:MSIL/Formbook.PRB!MTB removal tips

Malware Removal

The Trojan:MSIL/Formbook.PRB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Formbook.PRB!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/Formbook.PRB!MTB?


File Info:

crc32: F65649AC
md5: 6f504a7b0cd5b838915f8e5f9f66cdbf
name: vrtpycmy.pk1.exe
sha1: cca14e649848677e5acc0ee62985797f498cc9b0
sha256: ac4f388241ba5d60ddff968acf513f1a62f7735049f6d4f0048fd5a0164cc95e
sha512: 407b97006e608e7691e31b14a88f49b549ff4ddeeba014ce2995752c3d73de2c654786e18ad972aea9eb70694925695e4a18fcc85ca308af08a91a83f7a87ac4
ssdeep: 12288:m72iN/2iNJ1FgDmsYuj3tsGetshtE1zLmRq/y9:M1J17gDmsYujtsZtyE1zMq/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: qgOGRVD
Assembly Version: 1.0.0.0
InternalName: qgOGRVD.exe
FileVersion: 1.0.0.0
LegalTrademarks: XyuKJuI
Comments: XyuKJuI
ProductName: qgOGRVD
ProductVersion: 1.0.0.0
FileDescription: XyuKJuI
OriginalFilename: qgOGRVD.exe

Trojan:MSIL/Formbook.PRB!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.33867651
FireEyeGeneric.mg.6f504a7b0cd5b838
Qihoo-360Generic/Trojan.45b
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005671361 )
BitDefenderTrojan.GenericKD.33867651
K7GWTrojan ( 005671361 )
F-ProtW32/MSIL_Troj.VE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.33867651
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Formbook.f304a948
AegisLabTrojan.MSIL.Agensla.i!c
Endgamemalicious (high confidence)
SophosTroj/Keylog-AIR
ComodoMalware@#2197io2071smj
F-SecureTrojan.TR/Kryptik.eposj
DrWebBackDoor.SpyBotNET.17
TrendMicroTrojanSpy.MSIL.NEGASTEAL.DYSGVP
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.GenericKD.33867651 (B)
IkarusTrojan.Inject
CyrenW32/MSIL_Troj.VE.gen!Eldorado
AviraTR/Kryptik.eposj
MicrosoftTrojan:MSIL/Formbook.PRB!MTB
ArcabitTrojan.Generic.D204C783
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderThetaGen:NN.ZemsilF.34122.Dm0@amuuqVp
ALYacTrojan.GenericKD.33867651
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.VZJ
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.DYSGVP
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.EKUT!tr
Ad-AwareTrojan.GenericKD.33867651
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
MaxSecureTrojan.Malware.74499699.susgen

How to remove Trojan:MSIL/Formbook.PRB!MTB?

Trojan:MSIL/Formbook.PRB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment